Privacy

Privacy Policy

App: Pawpal  ยท  Operator: JoCoding, Inc.  ยท  Last updated: September 2026

1. Who operates Pawpal

Operator/controller: JoCoding, Inc.

Privacy and support contact: mu07010@jocoding.net

Business form: Delaware corporation ยท Registered address: 1111B S Governors Ave, STE 80543, Dover, DE 19904, United States ยท Telephone: +1 (231) 450-5622 ยท Website: jocoding.io

Privacy requests are handled through the email address above. We may ask for information needed to verify that a request comes from the account holder.

2. What Pawpal does

Pawpal connects two people โ€” including couples, long-distance partners, best friends, and family โ€” with one shared virtual dog. A person writes text or a drawing, the dog carries the letter to the other person, and the recipient can read it in the app. The Home Screen widget and iOS Live Activity show the delivery state; they do not show the letter itself.

3. Information used by the app

InformationWhy it is usedWhere it goes / notes
Anonymous account ID and session dataCreate and authenticate the account, enforce access, and keep the connection working.Pawpal's own server (Cloudflare Workers with a D1 database). The app later links the anonymous account to Apple identity when the user completes the Apple link flow.
Apple identity linkRecover the same Pawpal account after reinstalling or changing device.Sign in with Apple, verified by Pawpal's own server. Pawpal requests no name or email scope and the app does not intentionally use name or email.
Two APNs device tokensWake the Home Screen widget and start an iOS Live Activity when a letter arrives.One widget token and one Live Activity start token are stored separately. They are not standard notification message content.
Purchase recordGrant, re-sync, and revoke optional breed unlocks.The app sends the signed App Store transaction to Pawpal's server, which stores the transaction ID, product ID, purchase time, and refund status in Cloudflare D1 and ties it to the account. RevenueCat processes the purchase (see providers below). Apple processes the payment itself.
Letter text and drawingStore and deliver the content to the connected recipient.Cloudflare D1 database. A letter body or drawing is not sent to PostHog and is not included in the widget/APNs payload.
Invite code, couple and pet state, optional anniversary dateConnect exactly two accounts, render the shared room, and calculate the in-app day count.Cloudflare D1 database. The invite code is a six-character code. The app does not show online presence.
Report recordRecord a safety report and preserve the reported content after the original letter is removed.The current app sends the fixed reason inappropriate, not free-form text. The database snapshot includes letter ID, reporter ID, reason, body, drawing, and creation time.
Product analytics eventMeasure reliability and feature use.PostHog receives the typed event name and bounded values such as locale, app version, letter text/drawing presence, letter count, widget family, action type, and limited failure category. Letter content, drawing coordinates, invite/couple/letter IDs, and raw error text are not in the event contract.
Crash/error diagnosticDiagnose crashes and reliability problems.Release error tracking sends only privacy-sanitized exception level/type/handled state and bounded diagnostic values. The sanitizer removes user content, raw messages, and identifiers before the PostHog boundary.

4. Information we do not intentionally request

Pawpal has no advertising SDK, subscription, external payment flow, public social feed, or behavioral-advertising profile. The app has no camera, photo-library, location, contacts, or microphone permission API. It does not intentionally request a name, email address, phone number, physical address, precise location, contacts, or photo library. Optional breed unlocks are bought through Apple's In-App Purchase; Pawpal and its providers never receive your card or other payment-method details. Free-form letters can still contain personal or sensitive information if a user chooses to write it.

5. Providers and international transfers

Pawpal is operated from Korea but uses providers in more than one country. The current release configuration and source identify these paths:

ProviderRoleCountry / endpoint currently configured
CloudflareApplication server (Workers), database (D1), breed-pack file storage (R2), and a key-value cache for push provider tokens.Cloudflare's APAC region; no jurisdiction restriction is configured.
RevenueCat, Inc.In-app purchase processing for the optional breed unlock: product lookup, purchase and restore. It receives the Pawpal account ID (as the app user ID), App Store transaction and receipt data, and standard SDK device metadata (for example device model, OS and app version, locale, IP address).United States, under RevenueCat's published data-processing terms.
PostHogRelease product analytics and privacy-sanitized crash/error diagnostics. SDK lifecycle, screen-view, and element-autocapture settings are disabled; Pawpal sends typed product events and the configured error-tracking payload.https://us.i.posthog.com, United States processing endpoint.
Apple Inc.Sign in with Apple identity service, In-App Purchase payment (Apple is the merchant and holds your payment method), and Apple Push Notification service (APNs).Apple processes data under its published service and privacy terms.
CloudflareServes this static policy/support site at pawpal.jocoding.io.Website request processing and logs are controlled by the Cloudflare service configuration; no site analytics script or form storage is present in this landing source.
Google FontsLoads the fonts used by this website.Browser requests go to Google font hosts. This website provider is separate from the iOS app data path.

For users outside Korea, app data therefore moves to and is processed in the configured provider regions. Product analytics is sent to the United States endpoint above.

6. Access controls and operator access

Server-side identity checks prevent ordinary users from reading another account's connection or letters: every request is authorised against the calling account before any record is returned. Restricted server-side paths process the data needed for delivery, account deletion, and report handling, and operator access to report snapshots exists for safety operations.

7. Retention, deletion, and safety snapshots

  • Connection ended: disconnecting or blocking deletes that connection's letters, pet, and couple row. Blocking also prevents reconnection through the same relationship.
  • Account deletion: Settings calls the account deletion path, which removes the account's devices, preferences, invite attempts, blocks, couple data, sent letters, reports filed by that account, breed-unlock credits and purchase records, and then the authentication account. If the account was signed in with Apple, the server also asks Apple to revoke Pawpal's Sign in with Apple authorization, so Pawpal no longer appears as connected to your Apple Account. Unlocks bought for the deleted account cannot be moved to a new account. Deletion cannot be undone.
  • Ordinary letters: reading a letter sets its read state but does not automatically purge its text or drawing. The original remains in the database until the connection is ended/blocked or the applicable account-deletion path removes it; no separate read-letter time-to-live is configured.
  • Report snapshots: the fixed report reason inappropriate and body/drawing snapshot are retained separately from the deleted original letter for safety review. A report filed by another account may therefore outlive the reported author's deletion.
  • Analytics and diagnostics: after a successful account deletion, the app clears pending Widget events from the App Group queue and resets the local PostHog identity/session. This does not automatically erase events already delivered to PostHog; email the privacy contact above to request provider-side access or deletion.
  • Local device data: account/session and widget cache are cleared on the relevant in-app actions, subject to the operating system and the separate Apple account link. Device backups and provider logs can have their own retention rules.

8. Push, widgets, and Live Activities

The app does not request standard notification authorization. When the system has a Pawpal widget token or Live Activity start token, APNs carries a content-change or activity-start signal to wake the relevant iOS surface. Letter text is not put in that payload. Users control whether a widget is installed and whether Live Activities are allowed in iOS settings; network availability and iOS refresh rules can affect timing.

9. Your rights and how to use them

You can use Settings to disconnect, block, and delete. For access, correction, deletion, restriction, portability where applicable, or a privacy question, email mu07010@jocoding.net. We may need to verify that the request is from the account holder. Korean users may also contact the Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr) or the Korea Internet & Security Agency privacy infringement report center (118, privacy.kisa.or.kr).

Pawpal does not make an automated decision that determines a user's legal rights, eligibility, price, or access using profiling. Product analytics and the automatic report/block action are not an automated eligibility decision.

10. Age policy

Pawpal is intended for people 16 or older worldwide. It is not directed to children under 16, and the app does not verify age at sign-up. If you believe a person under 16 provided information, contact us; we will review the request and delete information where required.

11. Security and changes

App-to-server traffic uses HTTPS/TLS. Database policies and server-side checks protect account boundaries. No system is perfectly secure. We will post material changes here; Korean consumer-facing changes will be announced at least 7 days before taking effect and materially unfavorable changes at least 30 days before where required. A new consent may be required for a new processing purpose.

Privacy requests and safety concerns

mu07010@jocoding.net

For EU/EEA users, see the dedicated GDPR notice.